Access method, policy accompanying method, transmission method, SDN controller and medium
The SDN controller determines the VLAN binding relationship based on the terminal MAC address, which solves the problem that the scope of application of VLAN automatic follow-up when non-authenticated terminals access the network in a multi-service campus network, and realizes the terminal's rapid access to the corresponding VLAN and policy accompanying, broadening the scope of application of access methods and service policies.
Patent Information
- Application Number
- CN202311525828.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-15
- Publication Date
- 2025-05-16
AI Technical Summary
When a non-authenticated terminal accesses a network in a multi-service campus network, the scope of application of VLAN automatic follow-up is limited, and the scope of application of service policy follow-up provided is also limited.
Through a software-defined network (SDN) controller, based on the terminal's MAC address, the VLAN binding relationship of the terminal is determined from the binding relationship between the pre-stored MAC address and the VLAN, and the binding relationship is sent to the switch, so that the terminal can quickly access the corresponding VLAN even if it accesses in a non-authentication manner.
It realizes that non-authenticated terminals quickly access the corresponding VLAN in a multi-service campus network, broadens the scope of application of VLAN automatic follow-up access method, and improves the scope of application of service policies to ensure that the terminal always follows the security policies of the security group they belong to.
Smart Images

Figure CN120018135A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of communication technology, and in particular to an access method, a policy accompanying method, a transmission method, an SDN controller and a medium. Background Art
[0002] As campus networks continue to expand and become more complex, the types of services and the scale of terminals in campus networks are doubling day by day, which puts higher requirements on the service experience and operation and maintenance management of terminals in campus networks. In order to ensure the controllability of campus network security, application-level access policies can usually be deployed in the campus to allow terminals to access the network at specific locations in the campus in a non-authenticated manner.
[0003] In the related art, a terminal can access a campus network based on an authentication method. Taking the example of a terminal accessing a virtual local area network (VLAN) in a campus network, when a user successfully passes the network access control (NAC) authentication, the specified VLAN will be authorized to the terminal used by the user through the authentication server, and the switch will modify the VLAN to which the user belongs to the authorized VLAN, so that the terminal used by the user can access the authorized VLAN. In this way, the VLAN can automatically follow the user, so that the terminal used by the user in this multi-service campus network can quickly access the authorized VLAN no matter which switch it is connected to.
[0004] However, the above process can only be applied to authenticated terminals that access the network using the authentication method. In addition, other services provided by the campus network to the terminal, such as access permission control and data transmission quality assurance, usually require the user to pass the NAC authentication before the user's terminal can provide the corresponding services. This limits the scope of application of the entire access method and the scope of application of the service provision policy. Summary of the invention
[0005] The embodiments of the present application provide an access method, a policy following method, a transmission method, an SDN controller and a medium to solve the problem that when a non-authenticated terminal accesses a network in a multi-service campus network, the scope of application of the access method of VLAN automatic following is limited, and the scope of application of the service policy following provided is limited.
[0006] In order to achieve the above objectives, the embodiments of the present application adopt the following technical solutions:
[0007] According to a first aspect of an embodiment of the present application, an access method is provided, the method comprising:
[0008] A software defined network (English: Software Defined Network, abbreviated as SDN) controller receives first information sent by a first switch, where the first information includes a first physical address (English: Media Access Control Address, abbreviated as MAC address) of a terminal connected to the first switch;
[0009] The SDN controller determines, based on the first MAC address, a first binding relationship between the first MAC address and the first VLAN from at least one pre-stored binding relationship between a MAC address and a VLAN;
[0010] The SDN controller sends the first binding relationship to the first switch, so that the terminal accesses the first VLAN.
[0011] In the access method provided by the embodiment of the present application, after the terminal accesses the first switch, the SDN controller can determine the first binding relationship between the terminal's MAC address and the first VLAN from at least one pre-stored binding relationship between a MAC address and a VLAN based only on the terminal's MAC address. In this way, even if the terminal accesses the network in a non-authenticated manner, it can quickly access the corresponding first VLAN, realize automatic VLAN following, and broaden the scope of application of the access method of automatic VLAN following.
[0012] In combination with the first aspect, in a possible implementation manner, the first information further includes interface information of the first switch interface;
[0013] The first switch interface is an interface for the terminal to access the first switch; the method further includes:
[0014] The SDN controller determines that there is a corresponding second switch interface for the first MAC address;
[0015] The SDN controller sends the first binding relationship to the first switch when a first condition is met; wherein the first condition includes at least one of the following:
[0016] The first switch interface is a mobile interface;
[0017] The first switch interface and the second switch interface belong to the same service network;
[0018] The time at which the SDN controller receives the first information sent by the first switch is within a preset time period during which migration is allowed.
[0019] In combination with the first aspect and the foregoing possible implementation manner, in another possible implementation manner, after the SDN controller sends the first binding relationship to the first switch, the method further includes:
[0020] The SDN controller sends a deletion instruction to the second switch to instruct the second switch to delete the first binding relationship.
[0021] In combination with the first aspect and the foregoing possible implementation manner, in another possible implementation manner, the SDN controller sending the first binding relationship to the first switch includes:
[0022] The SDN controller sends the first binding relationship to the first switch, and opens the VLANs to which all accompanying interfaces are connected.
[0023] In combination with the first aspect, in another possible implementation manner, each of the binding relationships includes a binding relationship between a MAC address group and a VLAN, and the MAC address group includes at least one MAC address;
[0024] The SDN controller determines, based on the first MAC address, a first binding relationship between the first MAC address and the first VLAN from at least one pre-stored binding relationship between the MAC address and the VLAN, including:
[0025] The SDN controller determines a first MAC address group to which the first MAC address belongs;
[0026] The SDN controller determines, based on the first MAC address group, a first binding relationship between the first MAC address group and the first VLAN from the at least one binding relationship.
[0027] In combination with the first aspect and the foregoing possible implementation manner, in another possible implementation manner, after the SDN controller receives the first information sent by the first switch, the method further includes:
[0028] The SDN controller determines, based on the first MAC address, a first mapping relationship between the first MAC address and the first terminal security group from at least one pre-stored mapping relationship between a MAC address and a terminal security group, wherein different terminal security groups correspond to different security policies;
[0029] The SDN controller sends the first mapping relationship to the first switch to execute the security policy corresponding to the first terminal security group.
[0030] In combination with the first aspect and the foregoing possible implementation manner, in another possible implementation manner, after the SDN controller receives the first information sent by the first switch, the method further includes:
[0031] The SDN controller determines, based on the first MAC address, a second mapping relationship between the first MAC address and the first data transmission priority from at least one pre-stored mapping relationship between a MAC address and a data transmission priority;
[0032] The SDN controller sends the second mapping relationship to the first switch, so as to transmit the data of the terminal according to the first data transmission priority.
[0033] According to a second aspect of the embodiment of the present application, a policy following method is provided, the method comprising:
[0034] The SDN controller receives first information sent by the first switch, where the first information includes a first MAC address of a terminal connected to the first switch;
[0035] The SDN controller determines, based on the first MAC address, a first mapping relationship between the first MAC address and the first terminal security group from at least one pre-stored mapping relationship between a MAC address and a terminal security group, wherein different terminal security groups correspond to different security policies;
[0036] The SDN controller sends the first mapping relationship to the first switch to execute the security policy corresponding to the first terminal security group.
[0037] In conjunction with the second aspect, in another possible implementation manner, the first information further includes a first Internet Protocol address (English: Internet Protocol Address, abbreviated as IP) and a first virtual routing forwarding (English: Virtual Routing and Rorwarding, abbreviated as VRF) of the terminal;
[0038] The SDN controller sends the first mapping relationship to the first switch, including:
[0039] The SDN controller sends the first mapping relationship, the first IP, the first VRF, and the security policy corresponding to the first terminal security group to the first switch.
[0040] In combination with the second aspect and the above possible implementation manner, in another possible implementation manner, the first information further includes first event type information, the first event includes any one of the following: an add event, a delete event, or an update event, and the first event type information indicates a state of an interface of the terminal accessing the switch;
[0041] The SDN controller sends the first mapping relationship to the first switch, including:
[0042] In the case where the first event includes an add event, the SDN controller sends the first mapping relationship, the first IP, the first VRF, and a security policy corresponding to the first terminal security group to the first switch;
[0043] In the case where the first event includes a deletion event, the SDN controller sends the first mapping relationship and a deletion instruction to the first switch, where the deletion instruction instructs the first switch to delete the first IP, the first VRF, and the security policy corresponding to the first terminal security group;
[0044] In the case where the first event includes an update event, the SDN controller sends the first mapping relationship, the second IP, the first VRF, and the security policy corresponding to the first terminal security group to the first switch, where the second IP is the IP of the terminal after the access switch interface is changed.
[0045] The policy accompanying method provided in the embodiment of the present application can determine the security policy corresponding to the terminal security group to which the terminal belongs according to the MAC address of the terminal. In this way, even if the terminal accesses the network in a non-authenticated manner or changes the interface to access the network, the terminal will always follow the security policy corresponding to the terminal security group. This realizes the policy accompanying security management and improves the convenience of security management.
[0046] According to a third aspect of the embodiments of the present application, a transmission method is provided, the method comprising:
[0047] The SDN controller receives first information sent by the first switch, where the first information includes a first MAC address of a terminal connected to the first switch;
[0048] The SDN controller determines, based on the first MAC address, a second mapping relationship between the first MAC address and the first data transmission priority from at least one pre-stored mapping relationship between a MAC address and a data transmission priority;
[0049] The SDN controller sends the second mapping relationship to the first switch to transmit the data of the terminal according to the first data transmission priority.
[0050] In combination with the third aspect, in a possible implementation, the first data transmission priority includes a Differentiated Services Code Point (DSCP) coloring identifier corresponding to the first MAC address.
[0051] The transmission method provided in the embodiment of the present application can determine the data transmission priority corresponding to the terminal according to the MAC address of the terminal. In this way, even if the terminal accesses the network in an unauthenticated manner, data transmission can be performed according to the pre-stored data transmission priority, thereby ensuring the terminal network communication quality of users with high data transmission priority.
[0052] According to a fourth aspect of an embodiment of the present application, an SDN controller is provided. The SDN controller includes: a receiving unit, a determining unit, and a sending unit.
[0053] The receiving unit is configured to receive first information sent by the first switch, where the first information includes a first MAC address of a terminal connected to the first switch;
[0054] The determining unit is configured to determine, based on the first MAC address received by the receiving unit, a first binding relationship between the first MAC address and the first VLAN from at least one pre-stored binding relationship between a MAC address and a VLAN;
[0055] The sending unit is configured to send the first binding relationship determined by the determining unit to the first switch, so that the terminal accesses the first VLAN.
[0056] In conjunction with the fourth aspect, in a possible implementation manner, the first information further includes interface information of a first switch interface; the first switch interface is an interface for the terminal to access the first switch;
[0057] The determining unit is further configured to determine that there is a corresponding second switch interface for the first MAC address;
[0058] The sending unit is further configured to send the first binding relationship to the first switch when a first condition is met; wherein the first condition includes at least one of the following:
[0059] The first switch interface is a mobile interface;
[0060] The first switch interface and the second switch interface belong to the same service network;
[0061] The time at which the SDN controller receives the first information sent by the first switch is within a preset time period during which migration is allowed.
[0062] In combination with the fourth aspect and the foregoing possible implementation manner, in another possible implementation manner, the sending unit is further configured to send a deletion instruction to the second switch after sending the first binding relationship to the first switch, so as to instruct the second switch to delete the first binding relationship.
[0063] In combination with the fourth aspect and the foregoing possible implementations, in another possible implementation, the sending unit is specifically configured to send the first binding relationship to the first switch and open the VLANs to which all accompanying interfaces are connected.
[0064] In conjunction with the fourth aspect, in another possible implementation manner, each of the binding relationships includes a binding relationship between a MAC address group and a VLAN, and the MAC address group includes at least one MAC address;
[0065] The determining unit is specifically configured to:
[0066] Determine a first MAC address group to which the first MAC address belongs;
[0067] Based on the first MAC address group, a first binding relationship between the first MAC address group and the first VLAN is determined from the at least one binding relationship.
[0068] In conjunction with the fourth aspect, in another possible implementation manner, the SDN controller further includes: a transmission unit;
[0069] The determining unit is further configured to determine the data transmission priority corresponding to the first MAC address after the receiving module receives the first information sent by the first switch;
[0070] The transmission unit is configured to transmit the transmission data of the terminal on the first VLAN based on the data transmission priority determined by the determination unit.
[0071] For specific implementation methods, reference may be made to the behavior function of the SDN controller in the access method provided by the first aspect or the possible implementation methods of the first aspect.
[0072] According to a fifth aspect of an embodiment of the present application, an SDN controller is provided. The SDN controller includes: a receiving unit, a determining unit, and a sending unit.
[0073] The receiving unit is configured to receive first information sent by the first switch, where the first information includes a first MAC address of a terminal connected to the first switch;
[0074] The determining unit is configured to determine, based on the first MAC address received by the receiving unit, a first mapping relationship between the first MAC address and the first terminal security group from at least one pre-stored mapping relationship between a MAC address and a terminal security group, wherein different terminal security groups correspond to different security policies;
[0075] The sending unit is configured to send the first mapping relationship determined by the determining unit to the first switch, so as to execute the security policy corresponding to the first terminal security group.
[0076] For specific implementation methods, reference may be made to the behavior function of the SDN controller in the policy following method provided in the second aspect or the possible implementation methods of the second aspect.
[0077] According to a sixth aspect of an embodiment of the present application, an SDN controller is provided. The SDN controller includes: a receiving unit, a determining unit, and a sending unit.
[0078] The receiving unit is configured to receive first information sent by the first switch, where the first information includes a first MAC address of a terminal connected to the first switch;
[0079] The determining unit is configured to determine, based on the first MAC address received by the receiving unit, a second mapping relationship between the first MAC address and the first data transmission priority from at least one pre-stored mapping relationship between a MAC address and a data transmission priority;
[0080] The sending unit is configured to send the second mapping relationship determined by the determining module to the first switch, so as to transmit the data of the terminal according to the first data transmission priority.
[0081] For specific implementations, reference may be made to the behavior function of the SDN controller in the transmission method provided in the third aspect or a possible implementation of the third aspect.
[0082] In a seventh aspect of an embodiment of the present application, an SDN controller is provided, comprising a processor and a memory, the memory storing a program or instruction that can be run on the processor, wherein the program or instruction, when executed by the processor, implements the steps of the access method as described in the first aspect and the possible implementation manner of the first aspect, or implements the steps of the policy accompanying method as described in the second aspect and the possible implementation manner of the second aspect, or implements the steps of the transmission method as described in the third aspect and the possible implementation manner of the third aspect.
[0083] In an eighth aspect of an embodiment of the present application, a readable storage medium is provided, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the access method as described in the first aspect and the possible implementation of the first aspect are implemented, or the steps of the policy accompanying method as described in the second aspect and the possible implementation of the second aspect are implemented, or the steps of the transmission method as described in the third aspect and the possible implementation of the third aspect are implemented. BRIEF DESCRIPTION OF THE DRAWINGS
[0084] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.
[0085] Figure 1 A schematic diagram of the architecture of a traditional campus network provided for related technologies;
[0086] Figure 2 One of the flow charts of an access method provided in an embodiment of the present application;
[0087] Figure 3 A connection diagram for reporting a terminal MAC address provided in an embodiment of the present application;
[0088] Figure 4 A second flowchart of an access method provided in an embodiment of the present application;
[0089] Figure 5 A schematic diagram of a policy accompanying architecture of a terminal in a campus network provided in an embodiment of the present application;
[0090] Figure 6 A third flowchart of an access method provided in an embodiment of the present application;
[0091] Figure 7 A schematic diagram of a VLAN accompanying architecture when a non-authenticated terminal accesses a network provided in an embodiment of the present application;
[0092] Figure 8 A schematic diagram of a process for a user to obtain user account authentication information and MAC authentication information through authentication provided in an embodiment of the present application;
[0093] Fig. 9 A schematic diagram of a process of confirming a priority forwarding queue by an SDN controller provided in an embodiment of the present application;
[0094] Fig.10A fourth flowchart of an access method provided in an embodiment of the present application;
[0095] Fig.11 A flow chart of a strategy accompanying method provided in an embodiment of the present application;
[0096] Fig.12 A flow chart of a transmission method provided in an embodiment of the present application;
[0097] Fig.13 One of the schematic diagrams of the composition of an SDN controller provided in an embodiment of the present application;
[0098] Fig.14 A second schematic diagram of the composition of an SDN controller provided in an embodiment of the present application;
[0099] Fig.15 The third schematic diagram of the composition of an SDN controller provided in an embodiment of the present application. DETAILED DESCRIPTION
[0100] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0101] The terms "first", "second", etc. in the specification and claims of this application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the terms used in this way can be interchangeable under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first", "second", etc. are generally of the same type, and the number of objects is not limited. For example, the first object can be one or more.
[0102] In addition, the term "and / or" in this article is only a description of the association relationship between the associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship.
[0103] The terms "at least one (item)", "at least one of" and the like in the specification and claims of the present application refer to any one, any two or a combination of more than two of the objects included therein. For example, at least one (item) of a, b, and c can be represented by: "a", "b", "c", "a and b", "a and c", "b and c" and "a, b and c", where a, b, and c can be single or multiple. Similarly, "at least two (items)" refers to two or more, and its meaning is similar to that of "at least one (item)".
[0104] The following is an explanation of some concepts and / or terms involved in an access method, a policy accompanying method, a transmission method, an SDN controller and a medium provided in an embodiment of the present application.
[0105] 1. SDN is an independent network architecture. Its purpose is to solve the problems of slow (protocol) development, lack of "consistent" policy control, poor scalability, and strong vendor dependence caused by the complexity of the existing network. There are two main components in the SDN system: SDN controller and network equipment (switch).
[0106] 2. SDN controller: It is the core component in the SDN network structure. As the control plane of the entire network, it is responsible for the control behavior of the entire network. The SDN controller can control the corresponding network devices through the Network Configuration Protocol (NETCONF) and OpenFlow protocols to achieve the specified functions.
[0107] 3. VLAN
[0108] VLAN, or Virtual Local Area Network, is a communication technology that logically divides a physical LAN into multiple broadcast domains. It should be noted that all devices in a VLAN are in the same broadcast domain, and different VLANs are different broadcast domains. A VLAN is generally a logical subnet. Devices within a VLAN can communicate directly, but devices between VLANs cannot communicate directly. Usually, VLANs are isolated from each other, and different VLANs need to communicate with each other through three-layer devices. VLAN members are mostly based on switch port allocation. The so-called VLAN division usually refers to adding the switch interface to a specific VLAN, so that the device connected to the interface is also added to the VLAN.
[0109] 4. VLAN division based on MAC address (MAC-VLAN)
[0110] In view of office scenarios in campus networks, we surveyed multiple customers and found that wired offices are usually one terminal per person. Effective operation and maintenance management is achieved by binding terminals to people, so the identity of the user can be associated based on the terminal's MAC information.
[0111] Generally, mainstream vendors in the industry support the ability to divide VLANs based on MAC addresses. By matching the MAC addresses of terminals, the corresponding VLANs are bound. Dividing VLANs based on MAC addresses only processes untagged packets. For tagged packets, VLANs are divided based on network interfaces.
[0112] Specifically, when the message received by the switch interface is an untagged message, the switch will match the MAC-VLAN table entry according to the source MAC address of the message. If the match is successful, it will be forwarded according to the matched VLAN and priority. If the match fails, it will be matched according to other matching principles. For example, the MAC-VLAN table entry for full mask matching is usually a fixed hard table resource, without ACL resource occupation, which can meet large-scale access requirements.
[0113] 5. Authentication and authorization VLAN
[0114] When the terminal passes NAC authentication successfully, the authentication server will authorize the terminal to the specified VLAN, and the switch will change the VLAN to which the terminal belongs to the authorized VLAN. The authorized VLAN does not change the configuration of the switch interface.
[0115] When the priority of the authorized VLAN is higher than the static VLAN configured for the user, the VLAN that takes effect after the user authentication is successful is the authorized VLAN. Alternatively, if no static VLAN is configured for the user, and the priority of the authorized VLAN is higher than the default VLAN, the VLAN that takes effect after the user authentication is successful is the authorized VLAN. After the user goes offline, the static VLAN or default VLAN configured for the user continues to be used.
[0116] For example, when deploying the authorized VLAN capability:
[0117] 1) For the switch side, the interface dynamic VLAN jump function needs to be deployed;
[0118] 2) For the authentication server side, you need to set the following Remote Authentication Dial In User Service (RADIUS) standard attributes:
[0119] Tunnel-Type: Set to VLAN or 13.
[0120] Tunnel-Medium-Type: set to 802 or 6.
[0121] Tunnel-Private-Group-ID: can be VLAN ID, VLAN description, VLAN name, or VLAN Pool.
[0122] In the following, in conjunction with the accompanying drawings, the access method, policy accompanying method, transmission method, SDN controller and medium provided in the embodiments of the present application are described in detail through specific embodiments and their application scenarios.
[0123] Against the backdrop of digital transformation, as the scale of terminals in campus networks doubles day by day, higher requirements are placed on the service experience and operation and maintenance management of terminal access to the network.
[0124] At present, the network structure of most campus networks is usually a multi-service campus networking structure. Generally, a physical network is used to carry multiple service deployments in a multi-service campus network. Among them, the mainstream deployment solutions are VxLAN+VN and VLAN+Virtual Routing and Forwarding (English: Virtual Routing and Rorwarding, abbreviated as VRF). A VLAN usually belongs to only one service network, while a service network can contain multiple VLANs.
[0125] In the related art, a terminal can access the campus network based on authentication. Specifically, when a user successfully passes NAC authentication, the authentication server will authorize the designated VLAN to the terminal used by the user, and the switch will modify the VLAN to which the user belongs to the authorized VLAN, so that the terminal used by the user can access the authorized VLAN. In this way, the VLAN can automatically follow the user, so that the terminal used by the user in this multi-service campus can quickly access the authorized VLAN no matter which switch it is connected to.
[0126] However, since the above authentication method requires frequent authentication message interactions, the terminal online time is increased or authentication fails, which leads to network access abnormalities.
[0127] Two commonly used VLAN automatic following solutions are described below as examples.
[0128] Solution 1: Based on static VLAN configuration:
[0129] Taking the typical VxLAN+VN multi-service campus networking scenario as an example, the SDN controller can also modify the static VLAN configuration of the switch, such as setting the port-based VLAN ID (English: Port-base VLANIdentity document, abbreviated as PVID) value of the switch port, to enable users to access different VN networks.
[0130] However, although this solution is applicable to both authenticated terminals and non-authenticated terminals, it is necessary to ensure that the port VLAN of the switch to which the terminal migrates always remains consistent, and true VLAN automatic following cannot be achieved.
[0131] Solution 2: VLAN following implementation based on authentication and authorization VLAN
[0132] The commonly used authentication methods in general campus networks include the following three: 802.1x authentication method, MAC authentication method and network (WEB) authentication method.
[0133] For example, Figure 1 A system architecture of a traditional campus network is shown. Figure 1 As shown in the figure, the traditional campus network architecture is a three-layer architecture of "access + aggregation + core".
[0134] The core layer is the high-speed switching backbone of the network, and plays a vital role in the connectivity of the entire network. The aggregation layer is the "intermediary" between the network access layer and the core layer. It aggregates the workstations before they access the core layer to reduce the load on the core layer equipment. The aggregation layer has multiple functions such as implementing policies, security, workgroup access, routing between VLANs, and filtering source or destination addresses. The access layer provides workstation access to the local network segment. In the access layer, the number of workstations in the same network segment is reduced, and high-speed bandwidth can be provided to the workgroup. Switches can be divided into three types according to networking, namely access switches, aggregation switches, and core switches. Access switches generally have multiple ports to connect to a large number of terminals, and one port will be used as an uplink port to transmit data to the aggregation layer; aggregation switches mainly connect to switches in the access layer and transmit data to the core layer.
[0135] Taking the typical VxLAN+VN multi-service campus networking scenario as an example, combined with Figure 1 As shown, a VLAN following implementation scheme based on 802.1x authentication authorization VLAN includes the following steps a to e:
[0136] a. Configure 802.1x authentication on the authentication server.
[0137] b. The SDN controller is deployed as an authentication proxy or local authentication; or, a third-party authentication server is used to configure an authorized VLAN based on the username.
[0138] c. After the terminal passes authentication, the SDN controller or authentication server sends the authorized VLAN to the access switch.
[0139] d. After the terminal obtains the address from the corresponding VLAN and accesses the VN network, when the terminal migrates to another switch, the re-authentication process and VLAN authorization process will be triggered.
[0140] e. After the SDN controller completes the VLAN delivery, the terminal can access the VN network unchanged.
[0141] However, the above process can only be applied to authenticated terminals that access the network using the authentication method. In addition, other services provided by the campus network to the terminal, such as access permission control and data transmission quality assurance, usually require the user to pass the NAC authentication before the user's terminal can provide the corresponding services. This limits the scope of application of the entire access method and the scope of application of the service provision policy.
[0142] It should be noted that a terminal that accesses the network in an authenticated manner may be referred to as an authenticated terminal.
[0143] It should be noted that a terminal that accesses the network in a non-authenticated manner may be referred to as a non-authenticated terminal.
[0144] The embodiments of the present application can be applied to scenarios where terminals access the network in multi-service campus networks, especially multi-service campus network scenarios, to ensure that non-authenticated terminals quickly access the corresponding service network and that access to the service network remains unchanged after mobile office or workstation adjustment.
[0145] In the access method, policy accompanying method, transmission method, SDN controller and medium provided by the embodiment of the present application, after the terminal accesses the first switch, the SDN controller can determine the first binding relationship between the terminal's MAC address and the first VLAN from at least one pre-stored binding relationship between a MAC address and a VLAN based only on the terminal's MAC address. In this way, even if the terminal accesses the network in a non-authenticated manner, it can quickly access the corresponding first VLAN, realize automatic VLAN following, and broaden the scope of application of the access method of automatic VLAN following.
[0146] Figure 2 The flowchart of an access method provided in an embodiment of the present application is applied to an SDN controller. Figure 2 As shown, the access method may include the following steps 201 to 203.
[0147] Step 201: The SDN controller receives first information sent by a first switch.
[0148] The first information may include a first MAC address of a terminal connected to the first switch.
[0149] In the embodiment of the present application, the first switch may be a switch to which a terminal is connected and which is connected to an SDN controller.
[0150] In the embodiment of the present application, the first MAC address of the terminal is an address that can be used to confirm the physical location of the terminal.
[0151] It is understandable that the first MAC address is written into the hardware by the terminal manufacturer when it is produced. The first MAC address can be used to identify the network card when the terminal accesses the network. If a terminal has multiple network cards, each network card needs and will have a unique MAC address. In other words, the MAC address of the terminal will not change. Therefore, the terminal connected to the switch can be determined by the MAC address of the terminal.
[0152] Optionally, in the embodiment of the present application, the first switch may report the first MAC address of the terminal connected to the first switch to the SDN controller.
[0153] Exemplarily, the first switch may send the first MAC address of the terminal accessing the first switch to the SDN controller through a network management protocol (English: Simple Network Management Protocol, abbreviated as SNMP) TRAP channel.
[0154] Optionally, in an embodiment of the present application, based on the reliability of the SNMP channel, that is, the User Datagram Protocol (UDP) mechanism, and considering the possibility of a hash conflict with the first MAC address of a traditional forwarding terminal, in order to ensure accurate reporting of the MAC address of a non-authenticated terminal without omissions, a remote procedure call (GRPC) channel can be linked to assist in reporting through the switch and periodically query the SDN controller to obtain the first MAC address of the terminal.
[0155] For example, Figure 3 As shown, the SDN controller 31 can open the SNMP TRAP channel. Optionally, the SDN controller 31 can also subscribe to the GRPC channel and the NETCONF / SNMP GET periodic query. Figure 332 is the core switch. Aggregation switch 33 can enable the GRPC Address Resolution Protocol (ARP) reporting channel and enable the GRPC Dynamic Host Configuration Protocol (DHCP) monitoring event reporting. Access switch 34 can enable the SNMP TRAP channel. In addition, access switch 34 can also enable the GRPC MAC reporting channel and the GRPC DHCP reporting channel.
[0156] Step 202: The SDN controller determines, based on the first MAC address, a first binding relationship between the first MAC address and the first VLAN from at least one pre-stored binding relationship between a MAC address and a VLAN.
[0157] In the embodiment of the present application, the binding relationship between the MAC address and the VLAN may represent the corresponding relationship between the VLANs that the terminal to which the MAC address belongs expects to use.
[0158] Optionally, in the embodiment of the present application, the pre-stored binding relationship between the at least one MAC address and the VLAN may be a binding relationship between the MAC address of the terminal and the VLAN pre-entered by a network administrator.
[0159] Optionally, in the embodiment of the present application, the pre-stored binding relationship between the at least one MAC address and the VLAN may also be obtained by batch pre-binding.
[0160] Exemplarily, the SDN controller can create a terminal user group, so that the network administrator can import the MAC addresses of the terminals in batches and establish a MAC address and VLAN binding relationship table.
[0161] Optionally, in the embodiment of the present application, the first binding relationship may indicate that after the terminal accesses the first switch, it is expected to access the first VLAN. In this way, the SDN controller determines the first binding relationship between the first MAC address and the first VLAN from the pre-stored binding relationship between at least one MAC address and the VLAN, so that the terminal can successfully access the first VLAN.
[0162] Optionally, in an embodiment of the present application, if the SDN controller fails to determine the first binding relationship between the first MAC address and the first VLAN from the pre-stored binding relationship between at least one MAC address and VLAN, the terminal can enter the SDN controller's terminal pool to be connected to the network, and the SDN controller can optionally be set based on the authority management policy of the terminal pool to be connected to the network to ensure that the terminal can access the network in a trusted manner.
[0163] Optionally, in an embodiment of the present application, the permission management and control of the above-mentioned terminal pool to be connected to the network may include permission to restrict network access and permission not to restrict network access.
[0164] Exemplarily, for restricting network access rights, the default behavior of the terminal pool to be connected to the network is that the terminal cannot access any network resources. The SDN controller can achieve this by sending a black hole MAC of the terminal's MAC address to the first switch, that is, matching the source MAC address of the terminal with the black hole MAC table entry, so that the terminal's data traffic cannot be forwarded.
[0165] For example, for permissions that do not restrict network access, the SDN controller can set the default behavior of the pool of terminals to be connected to the network to no restrictions, and the SDN controller will not send the black hole MAC of the terminal's MAC address to the first switch. At this time, the network administrator can obtain a temporary address based on the DHCP network segment corresponding to the default VLAN configuration of the interface connected to the terminal, and require the default lease to be set to 1 minute, so that after the administrator completes the binding of the terminal MAC and VLAN, the non-authenticated terminal can quickly obtain a new DHCP address to access the service network.
[0166] Optionally, in an embodiment of the present application, in a multi-service campus network, one service network may correspond to multiple switches. Therefore, when a terminal migrates between different accompanying interfaces of a switch under the same service network, the SDN controller may determine the VLAN to be accessed by the terminal based on the binding relationship between at least one pre-stored MAC address and the VLAN, so that the terminal can use the same VLAN after migration, thereby realizing automatic VLAN following.
[0167] For example, the SDN controller pre-stores the binding relationship between the MAC address of terminal 1 and VLAN1. After terminal 1 changes the switch interface a that accesses VLAN1 to switch interface b, the SDN controller can send the binding relationship between the MAC address of terminal 1 and VLAN1 to the switch where switch interface b is located, so that terminal 1 can still access VLAN1 at switch interface b, thereby realizing automatic VLAN following.
[0168] In this way, when the terminal migrates between different accompanying interfaces of the switch under the same service network, the SDN controller can always determine the VLAN to be accessed based on the MAC address of the terminal without being affected by the interface changes caused by the migration, thus achieving true VLAN mobility, so that the VLAN accessed by the terminal can migrate as the terminal migrates.
[0169] Step 203: The SDN controller sends a first binding relationship to the first switch, so that the terminal accesses the first VLAN.
[0170] Optionally, in an embodiment of the present application, after determining the binding relationship between the first MAC address of the terminal and the first VLAN, the SDN controller may send the first binding relationship to the first switch, so that the first switch can enable the terminal to access the first VLAN based on the first binding relationship.
[0171] Exemplarily, after determining the binding relationship between the first MAC address of the terminal and the first VLAN, the SDN controller may send a MAC-VLAN table to the first switch through the NETCONF channel, so that the terminal accesses the first VLAN.
[0172] Optionally, in the embodiment of the present application, the SDN controller can also perform unified operation and management of the terminals connected to the network, including terminal information viewing, key event visualization, and management operations such as switching service networks.
[0173] Optionally, in an embodiment of the present application, the SDN controller may also establish a reconciliation mechanism with the switch to compare the binding relationship between at least one MAC address and VLAN pre-stored in the SDN controller with the binding relationship between the MAC address and VLAN received in the switch, thereby ensuring the correctness and reliability of the binding relationship between at least one MAC address and VLAN pre-stored in the switch.
[0174] Optionally, in the embodiment of the present application, the SDN controller may reconcile with the switch within a predetermined time.
[0175] Exemplarily, the SDN controller may reconcile with the switch during the night time period.
[0176] In the access method provided by the embodiment of the present application, after the terminal accesses the first switch, the SDN controller can determine the first binding relationship between the terminal's MAC address and the first VLAN from at least one pre-stored binding relationship between a MAC address and a VLAN based only on the terminal's MAC address. In this way, even if the terminal accesses the network in a non-authenticated manner, it can quickly access the corresponding first VLAN, realize automatic VLAN following, and broaden the scope of application of the access method of automatic VLAN following.
[0177] Optionally, in the embodiment of the present application, combined with Figure 2 ,like Figure 4 As shown, the above step 203 may include the following step 203a.
[0178] Step 203a: The SDN controller sends the first binding relationship to the first switch, and opens the VLANs to which all accompanying interfaces are connected.
[0179] Optionally, in an embodiment of the present application, all the above-mentioned accompanying interfaces may include accompanying interfaces in all switches corresponding to the service network to which the first VLAN belongs in the first binding relationship.
[0180] Optionally, in an embodiment of the present application, the accompanying interface may indicate that a VLAN accessed by the terminal on the interface may be migrated along with the terminal.
[0181] Optionally, in an embodiment of the present application, the SDN controller may define some or all of the interfaces of the switch as accompanying interfaces, so that terminals accessing the VLAN through the accompanying interfaces can trigger automatic VLAN following during the migration process, thereby allowing the terminals to access the same VLAN when migrating between different accompanying interfaces.
[0182] Exemplarily, the SDN controller may add accompanying labels to some interfaces of the switch, and define the some interfaces as accompanying interfaces.
[0183] It is understandable that before the SDN controller sends the first binding relationship to the first switch, the accompanying interface cannot access the first VLAN. Only after the SDN controller opens the VLAN corresponding to the accompanying interface, the terminal can access the corresponding first VLAN through the accompanying interface.
[0184] Optionally, in an embodiment of the present application, the SDN controller can open the VLANs to which all accompanying interfaces are connected while sending the first binding relationship to the first switch. This allows the terminal to directly access the VLAN through the accompanying interface during the migration between different accompanying interfaces without having to wait for the SDN controller to open the VLAN to which the accompanying interface is connected again, thereby improving the efficiency of VLAN accompanying.
[0185] Exemplarily, the SDN controller may send the MAC-VLAN table entry to the first switch through the NETCONF channel, and allow all VLANs to which the accompanying interfaces are connected.
[0186] In this way, since the SDN controller can open the VLANs accessed by all accompanying interfaces while sending the first binding relationship to the first switch, it can ensure that the terminal can quickly complete migration between different accompanying interfaces and quickly access the VLAN before migration through the accompanying interface after migration.
[0187] Optionally, in an embodiment of the present application, each of the above binding relationships may include a binding relationship between a MAC address group and a VLAN, and the MAC address group may include at least one MAC address.
[0188] Optionally, in the embodiment of the present application, the above step 202 may include the following step 202b and step 202c.
[0189] Step 202b: The SDN controller determines a first MAC address group to which the first MAC address belongs.
[0190] Step 202c: The SDN controller determines, based on the first MAC address group, from at least one binding relationship, a first binding relationship between the first MAC address group and the first VLAN.
[0191] Optionally, in an embodiment of the present application, each MAC address in the above MAC address group may correspond to a terminal, and the MAC address group may correspond to a terminal group.
[0192] Optionally, in an embodiment of the present application, after receiving the first MAC address sent by the first switch, the SDN controller can first determine the first MAC address group to which the first MAC address belongs, so that the SDN controller can determine the VLAN to which the terminal corresponding to the first MAC address is to access based on the binding relationship between the MAC address group and the VLAN.
[0193] It should be noted that in a multi-service campus network, wired office usually corresponds to one terminal for one user. Therefore, the terminal can be bound to the user to achieve effective operation and maintenance management.
[0194] Optionally, in an embodiment of the present application, a network administrator may perform batch management on a group basis on MAC address groups pre-stored in the SDN controller.
[0195] Exemplarily, a network administrator may import MAC addresses in a MAC address group in batches.
[0196] Exemplarily, the network administrator can modify the binding relationship between the MAC addresses and VLANs in a MAC address group in batches.
[0197] In this way, since the binding relationship between the MAC address and the VLAN can be determined based on the MAC address group to which the MAC address belongs, on the one hand, the VLANs to be accessed by the terminals can be managed in batches, improving the convenience of VLAN management; on the other hand, the terminal can use the VLAN bound to the MAC address group to which the MAC address of the terminal belongs, no matter where it migrates to in the network, thus realizing VLAN policy mobility.
[0198] Optionally, in the embodiment of the present application, after the above step 201, the access method provided in the embodiment of the present application may further include the following steps 204 and 205.
[0199] Step 204: The SDN controller determines, based on the first MAC address, a first mapping relationship between the first MAC address and the first terminal security group from at least one pre-stored mapping relationship between a MAC address and a terminal security group.
[0200] Different terminal security groups correspond to different security policies.
[0201] Step 205: The SDN controller sends the first mapping relationship to the first switch, so that the first switch executes the security policy corresponding to the first terminal security group.
[0202] Optionally, in the embodiment of the present application, the SDN controller can associate the identity of the user of the terminal with the terminal based on the MAC address of the terminal, divide the terminal security group to which the terminal belongs based on the MAC address of the terminal, and add a MAC-Based type terminal security group. In this way, the SDN controller can manage users and terminals by managing the MAC-Based type terminal security group.
[0203] Exemplarily, the network administrator may import the MAC address of the terminal into the terminal security group corresponding to the type to the SDN controller.
[0204] Optionally, in an embodiment of the present application, the security policy corresponding to the terminal security group may indicate the access rights of the terminals in the terminal security group. That is, through the security policy corresponding to the terminal security group to which the terminal belongs, the SDN controller may determine the resources that the terminal is allowed to access and the resources that it is not allowed to access.
[0205] Optionally, in an embodiment of the present application, a MAC-Based terminal security group may identify identity characteristics of its terminal security group members by the MAC address of the terminal.
[0206] For example, after the terminal accesses the VLAN, the switch can report the terminal's ARP / ND table entry to the SDN controller through the GRPC channel, so that the SDN controller can obtain the terminal's IP, VRF and terminal security group information. Then, the SDN controller can send or delete the IP and terminal security group information to the access switch according to the event type of the reported item.
[0207] It should be noted that the ARP / ND entry contains the mapping relationship between the IP address and the Mac address.
[0208] Optionally, in an embodiment of the present application, the ARP / ND table entry may include the MAC address, IP, VRF, and event type of the terminal. In this way, the SDN controller can obtain the IP, VRF, and security policy of the terminal security group corresponding to the MAC address of the terminal through the ARP / ND table entry. Therefore, after the SDN controller sends the first mapping relationship to the first switch, the first switch can manage the access rights of the terminal according to the VRF and IP of the terminal and the corresponding security policy.
[0209] It is understandable that during the migration of a terminal to different accompanying interfaces, the terminal security group to which the terminal belongs remains unchanged, and the policy based on the terminal security group remains unchanged, so as to achieve the effect of policy accompanying.
[0210] Optionally, in an embodiment of the present application, during the migration of the terminal to different accompanying interfaces, the first switch can report the ARP / ND table entries of the terminal in real time. In this way, when the terminal IP changes, the SDN controller can immediately perceive it and send the updated IP and terminal security group information to the access switch, so that the original IP information will be deleted after the ARP / ND table entry ages, and the controller will send the deletion event of the original IP and terminal security group information to the access switch, so as to achieve the decoupling of policy accompanying and IP.
[0211] For example, Figure 5 The diagram shows a schematic diagram of a policy-based architecture of a terminal in a campus network. The network architecture includes an SDN controller 51, a resource group 52, a core switch, an aggregation switch, and an access switch. Figure 5 , taking the SDN controller 51 setting the terminal security group A to inaccessible resource group 52 as an example. The policy accompanying the terminal in the campus network may include the following steps S1 to S5.
[0212] Step S1 : The SDN controller 51 parses and obtains the ARP / ND entry information of the reported terminal, thereby obtaining the MAC / VRF / IP information and event type.
[0213] Step S2: The SDN controller 51 may determine the corresponding relationship between the IP address and VRF of the terminal and the terminal security group A according to the MAC address of the terminal.
[0214] Optionally, in an embodiment of the present application, if the event type is an add or update event type, the SDN controller 51 can send the IP and terminal security group information to the entire network access switch; if the event type is a delete event, the SDN controller 51 can delete the IP and terminal security group information to the entire network access switch.
[0215] Step S3: After the SDN controller 51 determines the correspondence between the IP and VRF of the terminal and the terminal security group A, the SDN controller 51 determines that the terminal cannot access the resource group 52, and the data traffic of the terminal on the access switch 53 will be discarded.
[0216] Step S4: If the location of the terminal changes, from location 54 to location 55, the SDN controller 51 can re-parse and obtain the ARP / ND table entry information of the reported terminal, thereby obtaining the MAC / VRF / IP information and event type. And determine the corresponding relationship between the IP, VRF and terminal security group A of the terminal according to the MAC address of the terminal.
[0217] Optionally, in an embodiment of the present application, when the terminal IP changes, the updated IP and terminal security group information are sent to the entire network access switch; when the terminal IP does not change, no processing is performed.
[0218] Step S5: The SDN controller 51 may determine that the terminal is still unable to access the resource group 52, and the data traffic of the terminal on the access switch 56 will also be discarded.
[0219] In this way, since the security policy corresponding to the terminal security group to which the terminal belongs can be executed on the terminal according to the MAC address of the terminal, no matter which interface the terminal accesses the network from, the terminal always follows the security policy corresponding to the terminal security group. This realizes the policy-based security management and improves the convenience of security management.
[0220] Optionally, in the embodiment of the present application, the first information may further include interface information of a first switch interface; the first switch interface is an interface through which the terminal accesses the first switch.
[0221] Optionally, in the embodiment of the present application, combined with Figure 2 ,like Figure 6 As shown, before the above step 202, the access method provided in the embodiment of the present application may also include the following steps 206 and 207.
[0222] Step 206: The SDN controller determines that a corresponding second switch interface exists for the first MAC address.
[0223] Optionally, in the embodiment of the present application, the interface information of the first switch interface may be interface information of an interface through which the terminal accesses the first switch.
[0224] Optionally, in the embodiment of the present application, the interface information of the first switch interface may include, but is not limited to: configuration information of the first switch interface and topological location information of the first switch interface.
[0225] Optionally, in the embodiment of the present application, the second switch interface may be an interface to which the terminal with the first MAC address last accessed, or may be a fixed interface allocated by the second switch interface to the terminal with the first MAC address.
[0226] Optionally, in the embodiment of the present application, the interface to which the terminal with the first MAC address last accessed may be the same as or different from the first switch interface. This embodiment of the present application does not specifically limit this.
[0227] Optionally, in the embodiment of the present application, the SDN controller determining that the first MAC address has a corresponding second switch interface may indicate that the terminal with the first MAC address has accessed the first VLAN. Therefore, the SDN controller may still allow the terminal to access the first VLAN when managing the current access of the terminal, thereby achieving automatic VLAN following.
[0228] Step 207: When the first condition is met, the SDN controller sends the first binding relationship to the first switch.
[0229] The first condition may include one of the following:
[0230] The first switch interface is a companion interface;
[0231] The first switch interface and the second switch interface belong to the same service network;
[0232] The time at which the SDN controller receives the first information sent by the first switch is within a preset time period during which migration is allowed.
[0233] Optionally, in the embodiment of the present application, the first switch interface being a companion interface may indicate that when the terminal accesses the first switch interface, it is expected to access the first VLAN bound to the MAC address of the terminal. That is, when the terminal accesses the first switch interface, it is expected to follow the first VLAN.
[0234] Optionally, in an embodiment of the present application, the deployment elements of the accompanying interface may include but are not limited to: being a Hybrid interface; having MAC-VLAN enabled; having MAC learning / aging SNMP TRAP enabled; and NO DOT1x.
[0235] Optionally, in the embodiment of the present application, the first switch interface and the second switch interface belonging to the same service network may indicate that the terminal migrates in the same service network. Thus, when the terminal accesses the first switch interface, it can still access the first VLAN in the first binding relationship.
[0236] Exemplarily, the first switch interface and the second switch interface may belong to the same VN network.
[0237] Exemplarily, the first switch interface and the second switch interface may belong to the same VRF network.
[0238] Optionally, in the embodiment of the present application, the time when the SDN controller receives the first information sent by the first switch is within the preset time period for allowing migration, which may indicate that the time point when the terminal accesses the first switch is within the preset time period for allowing migration.
[0239] For example, assuming that the preset time period for allowing migration is every Monday, the terminal needs to access the first switch on Monday. In other words, the VLAN following during the migration of the terminal can be completed only during the preset time period for allowing migration.
[0240] It should be noted that the above steps 206 and 207 may be performed before step 201, or after step 201, or simultaneously with step 201. This application does not impose any specific limitation. Figure 6 The illustration only takes the fact that step 206 and step 207 may be performed before step 201 as an example.
[0241] For example, Figure 7 The figure shows a schematic diagram of the architecture of VLAN accompanying when a non-authenticated terminal accesses the network. The network architecture includes an SDN controller, a core switch, an aggregation switch, an access switch, and a terminal. Figure 7 As shown, the process of VLAN accompanying when the unauthenticated terminal accesses the network may include the following steps S6 to S9.
[0242] Step S6 : The switch 71 may send the MAC address of the terminal 73 and the interface information of the first switch interface to the SDN controller 72 .
[0243] Step S7: When the interface indicated by the interface information is a accompanying interface, the SDN controller 72 may determine a first binding relationship between the MAC address of the terminal 73 and the first VLAN from the pre-stored binding relationship between at least one MAC address and a VLAN.
[0244] Step S8: When the terminal 73 migrates between different accompanying interfaces of the same service network, the SDN controller may receive the MAC address of the terminal 73 and the interface information of the second switch interface sent by the switch 74.
[0245] Step S9. For the migration between different accompanying interfaces inside the switch 71, the SDN controller 72 may only update the controller interface location information; for the migration from the accompanying interface of the switch 71 to the accompanying interface of the switch 74, the SDN controller 72 may send the first binding relationship down to the switch 74 so that the terminal 73 can access the first VLAN through the switch 74.
[0246] Optionally, in the embodiment of the present application, since the first information may also include interface information of the first switch interface, the SDN controller may also perform visual management on the terminal controller interface.
[0247] Exemplarily, the SDN controller may control the visibility of information such as the MAC address, IP address, and access location (accessed switch, access port) of the terminal.
[0248] Exemplarily, the SDN controller may also record terminal key event logs, such as terminal migration information, service network switching information, online and offline information, configuration delivery log information, etc.
[0249] For example, the SDN controller can also control the terminal to switch the service network on the controller interface. For example, the network administrator can change the relationship between the terminal's MAC address and the VLAN binding table to switch the service network; or the SDN controller can send an interface flash disconnection method to quickly reacquire the DHCP address to access the new service network.
[0250] In this way, since the SDN controller determines that the terminal can access the first VLAN in the first binding relationship only when the first condition is met, it is possible to more accurately determine whether the terminal is migrated, thereby more accurately completing the VLAN automatic accompanying based on the terminal MAC address.
[0251] Optionally, in the embodiment of the present application, after the above step 203, the access method provided by the embodiment of the present application may further include the following step 208.
[0252] Step 208: The SDN controller sends a deletion instruction to the second switch to instruct the second switch to delete the first binding relationship.
[0253] Optionally, in an embodiment of the present application, the SDN controller may send down the binding relationship between the MAC address and the VLAN on demand according to the switch to which the terminal is connected, thereby avoiding an over-specification of the binding relationship table entries between the MAC address and the VLAN sent down by the entire network.
[0254] Optionally, in the embodiment of the present application, after the terminal completes the migration, the SDN controller sends a deletion instruction to the second switch to instruct the second switch to delete the first binding relationship to release the resource occupation of the first binding relationship in the second switch.
[0255] In this way, after the terminal accesses the first VLAN, the SDN controller sends a deletion instruction to the second switch to instruct the second switch to delete the first binding relationship. The deletion instruction can be sent to the second switch in a timely manner to instruct the second switch to delete the first binding relationship. Therefore, the resource occupation of the first binding relationship in the second switch can be released, saving the resources of the second switch.
[0256] Optionally, in an embodiment of the present application, after the above step 201, the access method provided in the embodiment of the present application may include the following steps 209 and 210.
[0257] Step 209: The SDN controller determines, based on the first MAC address, a second mapping relationship between the first MAC address and the first data transmission priority from at least one pre-stored mapping relationship between a MAC address and a data transmission priority.
[0258] Step 210: The SDN controller sends a second mapping relationship to the first switch to transmit the data of the terminal according to the first data transmission priority.
[0259] Optionally, in the embodiment of the present application, the data transmission priority may indicate the order in which the SDN controller transmits the transmission data of the terminal. It is understood that the higher the data transmission priority corresponding to the MAC address of the terminal, the higher the priority of the SDN controller in transmitting data to the terminal.
[0260] Optionally, in the embodiment of the present application, the SDN-based user experience guarantee scheme is a guarantee scheme that confirms the user's priority level based on the user's access information to the network, and then sets a priority message forwarding strategy for the switch. However, the basic process of the existing network user communication experience guarantee scheme requires that the user accesses the network through authentication by the authentication center, and the authentication center provides the user login information, authentication account information and other data of the access user to the SDN controller, and then the SDN controller determines whether to perform priority message forwarding and experience guarantee for the user based on the user information.
[0261] like Figure 8 As shown, the user obtaining the user account authentication information and the MAC authentication information through authentication may include the following steps A to C.
[0262] Step A: The user of the terminal passes the authentication of the authentication center and goes online.
[0263] Step B: The authentication center provides the SDN controller with the user's login account / terminal MAC address.
[0264] Step C: The SDN controller senses the authentication event and sends the priority forwarding configuration to the switch based on the VIP information.
[0265] It can be seen that in the relevant technology, only when the user passes the authentication of the authentication center can the user account authentication information and MAC authentication information be obtained.
[0266] It should be noted that in wireless network scenarios, users generally access the network through an authentication center. At this time, obtaining the user's login information through the authentication center and using the above login information as the basis for VIP user experience protection is generally feasible in wireless network scenarios. In wired network scenarios, many traditional customers do not want to access the network through an authentication center. Because in traditional wired networks, authentication centers are not necessary, and after adding authentication centers, each time you access the network, you need to authenticate, which brings additional operations to users who are accustomed to traditional networks, and will not be accepted by every user. At this time, the loss of the support of the authentication center makes the existing experience guarantee plan impossible to implement.
[0267] Optionally, in an embodiment of the present application, the SDN controller can actively collect the MAC address of the terminal connected to the first switch, determine the online data of the terminal, and automatically determine the data transmission priority corresponding to the MAC address of the terminal, and based on the data transmission priority, transmit the transmission data of the terminal on the first VLAN to ensure the user's communication experience.
[0268] Optionally, in an embodiment of the present application, a network administrator may collect the MAC address of a terminal, set a data transmission priority for the MAC address of the terminal, and enter the data into the SDN controller.
[0269] Exemplarily, the data transmission priority corresponding to the MAC address of the terminal may be set to a high-level user (English: Very Important Person, abbreviated as VIP).
[0270] Optionally, in an embodiment of the present application, the SDN controller may determine the data transmission priority corresponding to the first MAC address through a Differentiated Services Code Point (English: Differentiated Services Code Point, abbreviated as DSCP) coloring mark.
[0271] For example, Fig. 9 As shown, the process of the SDN controller confirming the priority forwarding queue according to the data transmission priority corresponding to the MAC of the terminal may include the following steps a to e.
[0272] Step a: The SDN controller sets a message priority forwarding channel on the core switch according to the VIP level.
[0273] Step b: The SDN controller receives the terminal MAC address online event sent by the switch, and determines the VIP user terminal online event.
[0274] Step c: The SDN controller may send the DSCP coloring configuration corresponding to the VIP user to the access switch to which it is connected.
[0275] Step d: The core switch obtains the DSCP coloring mark of the message and identifies that the current data is the data of the VIP user and needs to be forwarded preferentially.
[0276] Step e: The core switch forwards the identified VIP user data to the priority forwarding queue for forwarding.
[0277] In this way, since the transmission data of the transmission terminal on the first VLAN can be transmitted according to the data transmission priority corresponding to the MAC address, the terminal network communication quality of the user with high data transmission priority can be guaranteed.
[0278] Fig.10 The flowchart of a policy following method provided in an embodiment of the present application is applied to an SDN controller. Fig.10 As shown, the policy following method may include the following steps 301 to 303.
[0279] Step 301: The SDN controller receives first information sent by a first switch.
[0280] The first information includes a first MAC address of a terminal connected to the first switch.
[0281] Step 302: The SDN controller determines, based on the first MAC address, a first mapping relationship between the first MAC address and the first terminal security group from at least one pre-stored mapping relationship between a MAC address and a terminal security group.
[0282] Different terminal security groups correspond to different security policies.
[0283] Step 303: The SDN controller sends the first mapping relationship to the first switch to execute the security policy corresponding to the first terminal security group.
[0284] Optionally, in the embodiment of the present application, the first information further includes the IP and VRF of the terminal. The step 303 may include the following step 303a.
[0285] Step 303a: The SDN controller sends the first mapping relationship, the first IP, the first VRF, and the security policy corresponding to the first terminal security group to the first switch.
[0286] Optionally, in an embodiment of the present application, the first information further includes first event type information, the first event includes any of the following: an add event, a delete event, or an update event, and the first event type information indicates the state of the terminal access switch interface. The step 303 may include any of the following: step 303b, step 303c, or step 303d.
[0287] Step 303b: When the first event includes an add event, the SDN controller sends the first mapping relationship, the first IP, the first VRF, and the security policy corresponding to the first terminal security group to the first switch.
[0288] Step 303c: When the first event includes a deletion event, the SDN controller sends a first mapping relationship and a deletion instruction to the first switch, where the deletion instruction instructs the first switch to delete the security policy corresponding to the first IP, the first VRF, and the first terminal security group.
[0289] Step 303d: When the first event includes an update event, the SDN controller sends the first mapping relationship, the second IP, the first VRF, and the security policy corresponding to the first terminal security group to the first switch, where the second IP is the IP after the terminal changes the access switch interface.
[0290] For detailed descriptions of steps 301 to 303, reference may be made to the above-mentioned descriptions of steps 204 and 205. To avoid repetition, they will not be described again here.
[0291] The policy accompanying method provided in the embodiment of the present application can determine the security policy corresponding to the terminal security group to which the terminal belongs according to the MAC address of the terminal. In this way, even if the terminal accesses the network in a non-authenticated manner or changes the interface to access the network, the terminal will always follow the security policy corresponding to the terminal security group. This realizes the policy accompanying security management and improves the convenience of security management.
[0292] Fig.11 The flowchart of a transmission method provided in an embodiment of the present application is applied to an SDN controller. Fig.11 As shown, the transmission method may include the following steps 401 to 403.
[0293] Step 401: The SDN controller receives first information sent by a first switch.
[0294] The first information includes a first MAC address of a terminal connected to the first switch.
[0295] Step 402: The SDN controller determines, based on the first MAC address, a second mapping relationship between the first MAC address and the first data transmission priority from at least one pre-stored mapping relationship between a MAC address and a data transmission priority.
[0296] Step 403: The SDN controller sends a second mapping relationship to the first switch, so as to transmit the data of the terminal according to the first data transmission priority.
[0297] Optionally, in an embodiment of the present application, the first data transmission priority in the above step includes a Differentiated Services Code Point (DSCP) coloring mark corresponding to the first MAC address.
[0298] For detailed descriptions of steps 401 to 403, reference may be made to the above-mentioned descriptions of steps 209 and 210. To avoid repetition, they will not be described again here.
[0299] The transmission method provided in the embodiment of the present application can determine the data transmission priority corresponding to the terminal according to the MAC address of the terminal. In this way, even if the terminal accesses the network in an unauthenticated manner, data transmission can be performed according to the pre-stored data transmission priority, thereby ensuring the terminal network communication quality of users with high data transmission priority.
[0300] Fig.12 The following is an interactive flow chart of an access method provided in an embodiment of the present application. Fig.12 As shown, the access method may include the following steps 501 to 506.
[0301] Step 501: A terminal accesses a first switch.
[0302] Step 502: The first switch sends first information to the SDN controller.
[0303] The first information includes a first MAC address of a terminal connected to the first switch.
[0304] Step 503: The SDN controller receives first information sent by the first switch.
[0305] Step 504: The SDN controller determines, based on the first MAC address, a first binding relationship between the first MAC address and the first VLAN from pre-stored binding relationships between at least one MAC address and a virtual local area network VLAN.
[0306] Step 505: The SDN controller sends a first binding relationship to the first switch.
[0307] Step 506: The first switch controls the terminal to access the first VLAN.
[0308] Optionally, in the embodiment of the present application, the first information further includes interface information of the first switch interface; the first switch interface is an interface for the terminal to access the first switch; the access method provided in the embodiment of the present application further includes the following steps 507 and 508.
[0309] Step 507: The SDN controller determines that a corresponding second switch interface exists for the first MAC address.
[0310] Step 508: When the first condition is met, the SDN controller sends the first binding relationship to the first switch.
[0311] The first condition includes one of the following:
[0312] The first switch interface is a companion interface;
[0313] The first switch interface and the second switch interface belong to the same service network;
[0314] The time at which the SDN controller receives the first information sent by the first switch is within a preset time period during which migration is allowed.
[0315] Optionally, in the embodiment of the present application, after the above step 505, the access method provided in the embodiment of the present application may further include the following steps 509 and 510.
[0316] Step 509: The SDN controller sends a deletion instruction to the second switch.
[0317] Step 510: The second switch deletes the first binding relationship.
[0318] Optionally, in the embodiment of the present application, the above step 505 may include the following step 505a.
[0319] Step 505a: The SDN controller sends the first binding relationship to the first switch, and opens the VLANs to which all accompanying interfaces are connected.
[0320] Optionally, in an embodiment of the present application, each binding relationship includes a binding relationship between a MAC address group and a VLAN, and the MAC address group includes at least one MAC address; the above step 504 may include the following steps 504a and 504b.
[0321] Step 504a: The SDN controller determines a first MAC address group to which the first MAC address belongs.
[0322] Step 504b: The SDN controller determines, based on the first MAC address group, from at least one binding relationship, a first binding relationship between the first MAC address group and the first VLAN.
[0323] Optionally, in the embodiment of the present application, after the above step 501, the access method provided in the embodiment of the present application may further include the following steps 511 and 512.
[0324] Step 511: The SDN controller determines the terminal security group to which the terminal belongs based on the first MAC address.
[0325] Different terminal security groups correspond to different security policies.
[0326] Step 512: The SDN controller executes the security policy corresponding to the terminal security group to which the terminal belongs on the terminal.
[0327] Optionally, in the embodiment of the present application, after the above step 501, the access method provided in the embodiment of the present application may further include the following steps 513 and 514.
[0328] Step 513: The SDN controller determines the data transmission priority corresponding to the first MAC address.
[0329] Step 514: The SDN controller transmits the transmission data of the transmission terminal on the first VLAN based on the data transmission priority.
[0330] The above mainly introduces the solution provided by the embodiment of the present application from the perspective of the interaction between the SDN controller, the first switch and the terminal. It can be understood that in order to realize the above functions, the SDN controller, the first switch or the terminal includes hardware structures and / or software modules corresponding to the execution of each function. It should be easy for those skilled in the art to realize that, in combination with the algorithm steps of each example described in the embodiments disclosed in this article, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0331] The embodiment of the present application can divide the functional modules of the SDN controller, the first switch or the terminal according to the above method example. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one processing module. The above integrated module can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of modules in the embodiment of the present application is schematic and is only a logical function division. There may be other division methods in actual implementation.
[0332] In the case of dividing each functional module into corresponding functional modules, Fig.13 FIG. 4 shows a possible composition diagram of the SDN controller involved in the above embodiment. Fig.13 As shown, the SDN controller 110 may include: a receiving unit 111 , a determining unit 112 and a sending unit 113 .
[0333] The receiving unit 111 is used to receive first information sent by the first switch, where the first information includes a first MAC address of a terminal accessing the first switch; the determining unit 112 is used to determine, based on the first MAC address received by the receiving unit 111, a first binding relationship between the first MAC address and the first VLAN from at least one pre-stored binding relationship between a MAC address and a VLAN; and the sending unit 113 is used to send the first binding relationship determined by the determining unit 112 to the first switch, so that the terminal accesses the first VLAN.
[0334] In the embodiment of the present application, the first information further includes interface information of a first switch interface; the first switch interface is an interface through which the terminal accesses the first switch;
[0335] The determining unit 112 is further configured to determine whether the first MAC address has a corresponding second switch interface;
[0336] The sending unit 113 is further configured to send the first binding relationship to the first switch when a first condition is met; wherein the first condition includes one of the following:
[0337] The first switch interface is a mobile interface;
[0338] The first switch interface and the second switch interface belong to the same service network;
[0339] The time at which the SDN controller receives the first information sent by the first switch is within a preset time period during which migration is allowed.
[0340] In the embodiment of the present application, the sending unit 113 is further configured to send a deletion instruction to the second switch after sending the first binding relationship to the first switch, so as to instruct the second switch to delete the first binding relationship.
[0341] In the embodiment of the present application, the sending unit 113 is specifically configured to send the first binding relationship to the first switch and open the VLANs to which all accompanying interfaces are connected.
[0342] In the embodiment of the present application, each of the above binding relationships includes a binding relationship between a MAC address group and a VLAN, and the MAC address group includes at least one MAC address;
[0343] The determination unit 112 is specifically configured to:
[0344] Determine a first MAC address group to which the first MAC address belongs;
[0345] Based on the first MAC address group, a first binding relationship between the first MAC address group and the first VLAN is determined from at least one binding relationship.
[0346] In the embodiment of the present application, the SDN controller 110 further includes: an execution unit 114;
[0347] The determination unit 112 is further configured to determine the security group to which the terminal belongs based on the first MAC address after the receiving unit 111 receives the first information sent by the first switch, and different security groups correspond to different security policies;
[0348] The execution unit is used to execute the security policy corresponding to the security group to which the terminal belongs, as determined by the determination unit 112, on the terminal.
[0349] In the embodiment of the present application, the SDN controller 110 further includes: a transmission unit 115;
[0350] The determination unit 112 is further configured to determine the data transmission priority corresponding to the first MAC address after the receiving module receives the first information sent by the first switch;
[0351] The transmission unit 115 is configured to transmit the transmission data of the transmission terminal on the first VLAN based on the data transmission priority determined by the determination unit 112 .
[0352] In the case of dividing each functional module into corresponding functional modules, Fig.14 FIG. 4 shows a possible composition diagram of the SDN controller involved in the above embodiment. Fig.14 As shown, the SDN controller 140 may include: a receiving unit 141 , a determining unit 142 and a sending unit 143 .
[0353] The receiving unit 141 is configured to receive first information sent by the first switch, where the first information includes a first MAC address of a terminal connected to the first switch;
[0354] The determining unit 142 is configured to determine, based on the first MAC address received by the receiving unit 141, a first mapping relationship between the first MAC address and the first terminal security group from at least one pre-stored mapping relationship between a MAC address and a terminal security group, wherein different terminal security groups correspond to different security policies;
[0355] The sending unit 143 is configured to send the first mapping relationship determined by the determining unit 142 to the first switch, so as to execute the security policy corresponding to the first terminal security group.
[0356] In the case of dividing each functional module into corresponding functional modules, Fig.15 FIG. 4 shows a possible composition diagram of the SDN controller involved in the above embodiment. Fig.15 As shown, the SDN controller 150 may include: a receiving unit 151 , a determining unit 152 and a sending unit 153 .
[0357] The receiving unit 151 is configured to receive first information sent by the first switch, where the first information includes a first MAC address of a terminal connected to the first switch;
[0358] a determining unit 152, configured to determine, based on the first MAC address received by the receiving unit 151, a second mapping relationship between the first MAC address and the first data transmission priority from at least one pre-stored mapping relationship between a MAC address and a data transmission priority;
[0359] The sending unit 153 is configured to send the second mapping relationship determined by the determining module to the first switch, so as to transmit the data of the terminal according to the first data transmission priority.
[0360] It should be noted that all relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module and will not be repeated here.
[0361] It should be noted that the specific working process of each functional module in the SDN controller provided in the embodiment of the present application can refer to the specific description of the corresponding process in the method embodiment, and the embodiment of the present application will not be described in detail here. The SDN controller provided in the embodiment of the present application is used to execute the above-mentioned access method, policy accompanying method, and transmission method, so it can achieve the same effect as the above-mentioned access method, policy accompanying method, and transmission method.
[0362] Through the description of the above implementation methods, technical personnel in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0363] In the several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the modules or units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0364] The units described as separate components may or may not be physically separated, and the components shown as units may be one physical unit or multiple physical units, that is, they may be located in one place or distributed in multiple different places. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0365] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0366] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium, including several instructions to enable a device (which can be a single-chip microcomputer, chip, etc.) or a processor (processor) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (English: Read-Only Memory, abbreviated as ROM), random access memory (English: Random Access Memory, abbreviated as RAM), disk or optical disk and other media that can store program code.
[0367] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
Claims
1. An access method, characterized in that: The method comprises: The software defined network SDN controller receives first information sent by the first switch, where the first information includes a first MAC address of a terminal connected to the first switch; The SDN controller determines, based on the first MAC address, a first binding relationship between the first MAC address and the first VLAN from the pre-stored binding relationship between at least one MAC address and a virtual local area network VLAN; The SDN controller sends the first binding relationship to the first switch, so that the terminal accesses the first VLAN.
2. The method according to claim 1, characterized in that The first information also includes interface information of a first switch interface; the first switch interface is an interface for the terminal to access the first switch; the method also includes: The SDN controller determines that there is a corresponding second switch interface for the first MAC address; The SDN controller sends the first binding relationship to the first switch when a first condition is met; wherein the first condition includes at least one of the following: The first switch interface is a mobile interface; The first switch interface and the second switch interface belong to the same service network; The time at which the SDN controller receives the first information sent by the first switch is within a preset time period during which migration is allowed.
3. The method according to claim 2, characterized in that After the SDN controller sends the first binding relationship to the first switch, the method further includes: The SDN controller sends a deletion instruction to the second switch to instruct the second switch to delete the first binding relationship.
4. The method according to claim 1, characterized in that: The SDN controller sends the first binding relationship to the first switch, including: The SDN controller sends the first binding relationship to the first switch, and opens the VLANs to which all accompanying interfaces are connected.
5. The method according to claim 1, characterized in that Each of the binding relationships includes a binding relationship between a MAC address group and a VLAN, and the MAC address group includes at least one MAC address; The SDN controller determines, based on the first MAC address, a first binding relationship between the first MAC address and the first VLAN from at least one pre-stored binding relationship between the MAC address and the VLAN, including: The SDN controller determines a first MAC address group to which the first MAC address belongs; The SDN controller determines, based on the first MAC address group, a first binding relationship between the first MAC address group and the first VLAN from the at least one binding relationship.
6. The method according to any one of claims 1 to 5, characterized in that: After the SDN controller receives the first information sent by the first switch, the method further includes: The SDN controller determines, based on the first MAC address, a first mapping relationship between the first MAC address and the first terminal security group from at least one pre-stored mapping relationship between a MAC address and a terminal security group, wherein different terminal security groups correspond to different security policies; The SDN controller sends the first mapping relationship to the first switch to execute the security policy corresponding to the first terminal security group.
7. The method according to any one of claims 1 to 5, characterized in that: After the SDN controller receives the first information sent by the first switch, the method further includes: The SDN controller determines, based on the first MAC address, a second mapping relationship between the first MAC address and the first data transmission priority from at least one pre-stored mapping relationship between a MAC address and a data transmission priority; The SDN controller sends the second mapping relationship to the first switch, so as to transmit the data of the terminal according to the first data transmission priority.
8. A strategy following method, characterized in that: The method comprises: The SDN controller receives first information sent by the first switch, where the first information includes a first MAC address of a terminal connected to the first switch; The SDN controller determines, based on the first MAC address, a first mapping relationship between the first MAC address and the first terminal security group from at least one pre-stored mapping relationship between a MAC address and a terminal security group, wherein different terminal security groups correspond to different security policies; The SDN controller sends the first mapping relationship to the first switch to execute the security policy corresponding to the first terminal security group.
9. A transmission method, characterized in that: The method comprises: The SDN controller receives first information sent by the first switch, where the first information includes a first MAC address of a terminal connected to the first switch; The SDN controller determines, based on the first MAC address, a second mapping relationship between the first MAC address and the first data transmission priority from at least one pre-stored mapping relationship between a MAC address and a data transmission priority; The SDN controller sends the second mapping relationship to the first switch, so as to transmit the data of the terminal according to the first data transmission priority.
10. An SDN controller, characterized in that: The SDN controller includes: a receiving unit, a determining unit and a sending unit; The receiving unit is configured to receive first information sent by the first switch, where the first information includes a first MAC address of a terminal connected to the first switch; The determining unit is configured to determine, based on the first MAC address received by the receiving unit, a first binding relationship between the first MAC address and the first VLAN from at least one pre-stored binding relationship between a MAC address and a VLAN; The sending unit is configured to send the first binding relationship determined by the determining unit to the first switch, so that the terminal accesses the first VLAN.
11. An SDN controller, characterized in that: The device comprises: a receiving unit, a determining unit and a sending unit; The receiving unit is configured to receive first information sent by the first switch, where the first information includes a first MAC address of a terminal connected to the first switch; The determining unit is configured to determine, based on the first MAC address received by the receiving unit, a first mapping relationship between the first MAC address and the first terminal security group from at least one pre-stored mapping relationship between a MAC address and a terminal security group, wherein different terminal security groups correspond to different security policies; The sending unit is configured to send the first mapping relationship determined by the determining unit to the first switch, so as to execute the security policy corresponding to the first terminal security group.
12. An SDN controller, characterized in that: The device comprises: a receiving unit, a determining unit and a sending unit; The receiving unit is configured to receive first information sent by the first switch, where the first information includes a first MAC address of a terminal connected to the first switch; The determining unit is configured to determine, based on the first MAC address received by the receiving unit, a second mapping relationship between the first MAC address and the first data transmission priority from at least one pre-stored mapping relationship between a MAC address and a data transmission priority; The sending unit is configured to send the second mapping relationship determined by the determining module to the first switch, so as to transmit the data of the terminal according to the first data transmission priority.
13. An SDN controller, characterized in that: It includes a processor and a memory, the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, it implements the steps of the access method as described in any one of claims 1 to 7, or implements the steps of the policy accompanying method as described in claim 8, or implements the steps of the transmission method as described in claim 9.
14. A readable storage medium, characterized in that: The readable storage medium stores programs or instructions, and when the programs or instructions are executed by the processor, they implement the steps of the access method as described in any one of claims 1 to 8, or implement the steps of the policy accompanying method as described in claim 8, or implement the steps of the transmission method as described in claim 9.